Skip to main content
FixMyTech

How to Use Google Authenticator Without Losing Access

By

Published

8 min read

Share

Short answer

Install Google Authenticator, scan the QR code the service shows you, then enter the six-digit code to confirm. Before you leave that setup screen, save the recovery codes the service offers and turn on cloud sync in the app's settings. Without one of those two, a lost phone means recovering every account individually.

On this page

Google Authenticator is the default recommendation for a reason, and also the most common way people lock themselves out of their own accounts. The app is fine. The problem is that the dangerous part of the process happens in about four seconds, on a screen most people skip past.

Here is the setup done in the order that survives a lost phone, rather than the order the prompts put it in.

What the app is actually doing

When you scan a QR code, you are not pairing with a server. That QR encodes a shared secret, and the app stores it locally. From then on, both the app and the service run the same calculation — the secret, plus the current time rounded to a 30-second window, and arrive at the same six digits independently.

Three consequences follow from that, and they explain almost every question people have:

  • No internet is needed. The phone is doing arithmetic, not fetching a code.
  • The clock matters enormously. If your phone’s time drifts, the codes stop matching.
  • The secret cannot be recovered from the service. Google cannot resend it. Once it is only on a phone that is gone, it is gone.

This is also why the app works with services that have nothing to do with Google. It implements an open standard called TOTP, so any TOTP app handles any TOTP account.

Set it up in the right order

Pick one service to start with, and ideally not your main email — do a less critical account first so a mistake is cheap.

  1. Install the app. Google Authenticator on the App Store or Play Store. Check the publisher is Google; the stores carry convincing imitations.
  2. Turn on cloud sync first. Open the app, tap your profile icon, and sign into a Google account. The app then backs the secrets up to that account. Doing this before you add anything means every account you add is covered.
  3. Open the service’s 2FA settings. Usually under Security, Sign-in, or Account. Choose the authenticator app option rather than SMS.
  4. Scan the QR code with the app’s + button → Scan a QR code.
  5. Type the six-digit code back into the service to confirm the pairing. If you skip this, 2FA is not actually enabled.
  6. Save the recovery codes. This is the step that matters. Keep reading.

Do not leave the setup page without the recovery codes

Nearly every service shows a set of single-use backup codes during or just after 2FA setup. They are the officially supported way back in when the app is gone.

Save them before you close that page. Most services display them once. A few let you regenerate them later, but only while signed in, which is exactly the state you will not be in when you need them.

Put them somewhere that is not the phone running the app and not inside the account they unlock. Where to keep recovery codes covers the options honestly, including why a screenshot in your photo library is worse than it sounds.

The manual key, for when the camera route fails

Every QR code screen has a “can’t scan it?” link revealing a long text string. That string is the secret. You can type it into the app manually under Enter a setup key.

It is also something to handle carefully: anyone who photographs that screen can add your account to their own authenticator and generate valid codes indefinitely. Treat the QR code and the manual key as being as sensitive as the password itself.

What cloud sync does and does not cover

Google Authenticator’s sync feature backs your secrets up to a Google account. It solves the most common disaster, which is dropping the phone down a drain, and it is worth turning on.

It does not solve everything:

Scenario Sync helps?
New phone, same Google account Yes, codes restore on sign-in
Phone lost or broken Yes
Locked out of the Google account holding the sync No
You put your Google 2FA inside this app and lost the phone No, circular
Switching to a different authenticator app No, no export to third parties

That fourth row is the trap. If your Google account’s own second factor lives only in Google Authenticator, and the Authenticator backup lives in that same Google account, then losing the phone leaves you unable to reach either. Make sure your Google account has a second route: a passkey, a second device, or printed backup codes stored elsewhere.

Moving to a new phone

Do this before wiping the old one, which sounds obvious and is routinely ignored.

With sync on: install the app on the new phone, sign into the same Google account, and the accounts appear. Confirm a code works on a real login before you factory-reset the old phone.

Without sync: use the export feature. On the old phone, tap the menu → Transfer accounts → Export accounts, choose which to move, and the app produces a QR code. Scan it from the new phone’s import screen. Large numbers of accounts produce several QR codes in sequence.

That export QR contains every selected secret in plain form. Do not photograph it, do not screenshot it, and do not display it anywhere a camera can see.

If the old phone is already gone: there is no transfer. Each account must be recovered through its own provider, which is what recovering an account without your authenticator is about, and the outcome is not guaranteed.

When codes stop being accepted

The app says the code is valid, the site says it is wrong. Three causes, in order of likelihood.

Clock drift. The phone’s clock has slipped relative to real time. Set Settings → General → Date & Time → Set Automatically on iPhone, or Settings → System → Date & time → Set time automatically on Android. Google Authenticator on Android also has a Time correction for codes option in its settings that resyncs without touching the system clock.

Typing it after it expires. The code rotates every 30 seconds. If the coloured timer is nearly empty, wait for the next one rather than rushing.

The wrong entry. Several accounts from the same provider look identical in the list. Check the email address under the account name.

What to avoid

  • Screenshotting the QR code “as a backup”. It sits in your photo library, which is probably synced to a cloud account, which may be protected by the same 2FA that QR code sets up.
  • Enabling 2FA on ten accounts in one sitting. You will not save ten sets of recovery codes properly. Do two or three, then stop.
  • Removing SMS as a backup before the app is confirmed working. Sign out and back in once with the app first.
  • Relying on a single phone. A second device with the same secrets, or a password manager that also stores TOTP codes, costs nothing and removes the single point of failure entirely.

Realistic expectations

Set up properly, the app is nearly invisible. Most services only ask for a code on a new device or after months away, so a typical person opens the app a handful of times a year.

The failure mode is not the app breaking. It is a new phone, a factory reset, or a drowned handset combined with recovery codes nobody saved. Spend the extra sixty seconds on sync and the codes now, because the version of you that needs them will have no other option. Once your accounts are set up, it is also worth checking which devices are signed in to confirm nothing predates the change.

Frequently asked questions

Does Google Authenticator work without internet?
Yes. The codes are generated from a secret stored on the phone plus the current time, with no network involved. Airplane mode, no signal and no Wi-Fi all still produce valid codes.
Why is my code being rejected as wrong?
Almost always a clock drift problem. The codes depend on your phone's time matching the server's, so if the phone's clock has slipped by more than about thirty seconds every code fails. Setting the phone's date and time to automatic fixes it.
Is Google Authenticator only for Google accounts?
No. It implements the standard TOTP algorithm, so it works with any service offering authenticator-app 2FA, and other TOTP apps work with Google accounts equally well. The app name is misleading.
Can I have the same account on two phones?
Yes, if you scan the same QR code on both during setup, or use cloud sync. Two devices holding the same secret generate identical codes, which is a genuinely useful backup if you have an old phone sitting in a drawer.
What happens to my codes if I delete the app?
Without cloud sync enabled, the secrets are gone with the app and cannot be recovered from anywhere. With sync on, reinstalling and signing into the same Google account restores them.

All Accounts guides